Job Closed
This listing is no longer active.
Building a #BetterWorkingWorld by providing trust through assurance and helping organizations grow, transform & operate.
Senior Risk Consultant – Digital Risk, Application Security
Location
India
Posted
7 days ago
Salary
0
Seniority
Senior
Job Description
Senior Risk Consultant – Digital Risk, Application Security
EY
• Conduct application security assessments to identify and mitigate potential security risks. • Analyse software systems to identify potential threats and vulnerabilities. • Create and maintain threat models that outline potential attack vectors. • Collaborate with development teams to remediate identified vulnerabilities. • Validate threat models against industry standards. • Document findings from threat modelling assessments. • Review code written by developers to identify security flaws. • Perform various security tests, including SAST and DAST. • Provide technical guidance for application onboarding activities. • Work closely with development teams, product managers, and other stakeholders to gather information. • Design and implement process improvements for the Application Security program.
Job Requirements
- 4+ years of experience with various threat modelling tools and methodologies.
- 4+ years of experience in engineering, product/technical program management, data analysis, or product development.
- 4+ years of experience working in cross-functional and/or cross-team projects.
- 4+ years of combined experience in technology administration/management, technical risk management, and software development/engineering.
- Strong exposure working in client facing roles.
- Certifications such as CISSP or CEH are a plus.
- Basic to moderate coding skills and experience working on application or service development teams.
- Strong written and oral communication skills.
- Self-motivated with the ability to work independently.
- Strong analytical skills with the ability to think creatively and influence change.
Benefits
- Competitive salary
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Program Manager, Product Security (Remote USA or Canada)
CrowdStrikeCrowdStrike has redefined security with the world’s most advanced cloud-native platform that protects and enables the people, processes and technologies that drive modern enterprise. Tested and proven, the world's largest organizations trust CrowdStrike to stop breaches with unparalleled protection against the most sophisticated cyberattacks. The CrowdStrike culture has been built upon our Core Values since the day we began. We are Fanatical About the Customer, Relentlessly Focused on Innovation and believe that our Limitless Passion drives Unlimited Potential for every CrowdStriker. As a purpose-built remote-first company, we believe cultivating a connected culture for every employee, no matter where they are in the world, is a key ingredient in building a high-performing, diverse team. We don’t have a mission statement. We’re on a mission—to stop breaches. Ready to join a mission that matters?
As a global leader in cybersecurity, CrowdStrike protects the people, processes and technologies that drive modern organizations. Since 2011, our mission hasn’t changed — we’re here to stop breaches, and we’ve redefined modern security with the world’s most advanced AI-native platform. Our customers span all industries, and they count on CrowdStrike to keep their businesses running, their communities safe and their lives moving forward. We’re also a mission-driven company. We cultivate a culture that gives every CrowdStriker both the flexibility and autonomy to own their careers. We’re always looking to add talented CrowdStrikers to the team who have limitless passion, a relentless focus on innovation and a fanatical commitment to our customers, our community and each other. Ready to join a mission that matters? The future of cybersecurity starts with you. About the Role: We are CrowdStrike, a fast-growing security company focused on protecting our customers from cybersecurity attacks worldwide. We’re seeking an energetic, adaptable Program Manager to drive complex engineering projects in our Product Security organization. The Product Security team observes, assesses, mitigates, and resolves security threats across CrowdStrike’s product portfolio. You’ll drive scheduling, scoping, and execution of Product Security projects, working directly with teams and leadership across multiple organizations including Cybersecurity and Engineering to ensure timely roadmap delivery. You’ll collaborate cross-functionally to manage dependencies and drive critical issues to resolution. Required In lieu of a cover letter: In order to highlight what would make you a valuable asset to the CrowdStrike Cybersecurity team, we’d like to know what a day in your “project management” life looks like. More specifically, please tell us about ONE project in particular which required your leadership and fortitude to turn the tides of potential disaster. Using an intro paragraph to provide a brief summary of the problem the project was looking to solve and no more than five bullet points of “Actions Taken” by you specifically that led to the project’s successful outcome. What You'll Do: - Coach and mentor project teams in a collaborative, empathetic environment - Guide teams on best practices while allowing autonomy in implementation approaches - Create and manage project schedules from high-level phases to detailed tasks, including dependencies - Collaborate with worldwide business units to coordinate project involvement, goals, and expectations - Track project status and ensure schedules and priorities are met - Identify, track, and escalate critical issues through resolution - Manage project communication and status reporting cadences - Lead Scrum meetings and maintain action item follow-through - Drive continuous improvement through automation, AI, and process efficiencies - Flex engagement level across multiple projects—from hands-on execution on critical initiatives to high-level coaching and issue resolution across broader portfolios What You'll Need: - 5+ years in program/project management for software development or IT security - Experience with large-scale cloud platforms and complex interdependent technologies - Proven ability to manage and resolve persistent obstacles rather than avoid them - Strong knowledge of SDLC and Agile/Scrum/Project Management methodologies - Track record of owning programs/portfolios, scoping requirements, and planning milestones - Excellent written and verbal communication skills - Flexible approach, able to coach and apply Agile or traditional Project Management methods based on project needs - Comfortable leading critical discussions and presentations with engineers, managers, and executives - Thrives in consensus-driven, collaborative environments with proactive, open communication - Experience in influencing and supporting teams without direct authority - Effective when working cross-functionally across global divisions - Comfortable participating in and driving technical discussions - Meticulous attention to detail with strong decision-making abilities - Self-starter who proactively drives results in small team environments - Quick learner who takes initiative in fast-paced, evolving environments - Able to synthesize complex technical conversations into clear action items and next steps - Enthusiastic about receiving feedback and committed to continuous self-improvement #LI-Remote #LI-CS1 Benefits of Working at CrowdStrike: - Market leader in compensation and equity awards - Comprehensive physical and mental wellness programs - Competitive vacation and holidays for recharge - Paid parental and adoption leaves - Professional development opportunities for all employees regardless of level or role - Employee Networks, geographic neighborhood groups, and volunteer opportunities to build connections - Vibrant office culture with world class amenities - Great Place to Work Certified™ across the globe CrowdStrike is proud to be an equal opportunity employer. We are committed to fostering a culture of belonging where everyone is valued for who they are and empowered to succeed. We support veterans and individuals with disabilities through our affirmative action program. CrowdStrike is committed to providing equal employment opportunity for all employees and applicants for employment. The Company does not discriminate in employment opportunities or practices on the basis of race, color, creed, ethnicity, religion, sex (including pregnancy or pregnancy-related medical conditions), sexual orientation, gender identity, marital or family status, veteran status, age, national origin, ancestry, physical disability (including HIV and AIDS), mental disability, medical condition, genetic information, membership or activity in a local human rights commission, status with regard to public assistance, or any other characteristic protected by law. We base all employment decisions--including recruitment, selection, training, compensation, benefits, discipline, promotions, transfers, lay-offs, return from lay-off, terminations and social/recreational programs--on valid job requirements. If you need assistance accessing or reviewing the information on this website or need help submitting an application for employment or requesting an accommodation, please contact us at recruiting@crowdstrike.com for further assistance. Find out more about your rights as an applicant. CrowdStrike participates in the E-Verify program. Notice of E-Verify Participation Right to Work For detailed information about the U.S. benefits package, please click here. CrowdStrike Canada ULC is committed to equal pay for equal work in its compensation practices. The base salary range for this position in Canada is $115,000 - $165,000 CAD per year + variable/incentive compensation + equity + benefits. A candidate’s salary is determined by various factors including, but not limited to, relevant work experience, skills, certifications and location. This is Canadian-based employment, and it is expected that all employees maintain legal entitlement to work in Canada. Applicants selected to move forward in the hiring process are subject to background checks, including but not limited to criminal record, credit, and/or reference checks. Expected Close Date of Job Posting is:07-18-2026
Cybersecurity Expert - AI Specialist
MercorCincinnatus is an enterprise staffing company that partners with leading technology companies to source and employ highly skilled professionals for full-time and long-term contingent roles. Cincinnatus serves as the employer of record for these engagements, providing W-2 employment, payroll, benefits, and compliance, while placing employees directly within client teams to work on high-impact initiatives. Roles hired through Cincinnatus are not project-based or freelance engagements. They are structured, role-based positions that typically involve full-time or fixed-term commitments, close collaboration with a client's internal teams, and integration into standard enterprise workflows. Cincinnatus is a legal entity separate from Mercor. While opportunities may be discovered through Mercor's platform, employment, onboarding, payroll, and benefits for these roles are administered by Cincinnatus. Equal Employment Opportunity Cincinnatus is proud to be an Equal Employment Opportunity employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, reproductive health decisions, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, genetic information, political views or activity, or any other legally protected characteristic. Cincinnatus is committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans throughout the job application process.
Role Description Mercor connects elite creative and technical talent with leading AI research labs. Headquartered in San Francisco, our investors include Benchmark, General Catalyst, Peter Thiel, Adam D'Angelo, Larry Summers, and Jack Dorsey. Position: Cybersecurity Experts Type: Contract Compensation: $70–$90/hour Location: Remote Duration: ~2 months Role Responsibilities - Analyze and review content for security vulnerabilities with a focus on pattern recognition and classification in an AI context. - Apply expertise in systems programming and security concepts to enhance AI model threat detection and reasoning. - Work independently and asynchronously with a team of experts to solve real-world problems. - Craft, solve, and review challenging problems with real-world applicability. - Collaborate to improve AI model performance and security assessment. Qualifications - 2+ years of experience in programming with low-level languages such as C, C++, or Java. - Familiarity with security vulnerability classification frameworks like OWASP or CVEs. - Understanding of core cybersecurity concepts, including web security and common attack vectors. - Strong attention to detail and pattern recognition skills. - Clear written and verbal communication in English. - Based in the U.S., Canada, UK, Australia, or New Zealand. - Ability to pass an enhanced background check. Requirements - Start Date: Mid-April; exact dates confirmed closer to the start date. - Interview Process: Short interview and questionnaire to assess domain expertise. - Paid for up to 1 hour of onboarding time, including screening and onboarding videos if hired. - Application Process (Takes 20–30 mins to complete): Upload resume, AI interview based on your resume, Submit form. Resources & Support - For details about the interview process and platform information, please check: https://talent.docs.mercor.com/welcome - For any help or support, reach out to: support@mercor.com - Our team reviews applications daily. Please complete your AI interview and application steps to be considered for this opportunity.
Role Description Für unseren Kunden suchen wir einen Third Party Cyber Security Risk Expert (d/m/w/x). In dieser Position bist du maßgeblich an der Weiterentwicklung und Umsetzung des Third Party Cyber Risk Managements beteiligt. Du begleitest den gesamten Prozess von der Risikoanalyse bis zur Implementierung geeigneter Maßnahmen und fungierst als zentraler Ansprechpartner für alle Themen rund um Cyber Security Risiken bei externen Partnern und Lieferanten. - Weiterentwicklung und Umsetzung von Third Party Cyber Risk Management Strategien - Durchführung von Risikoanalysen sowie Entwicklung geeigneter Sicherheitsmaßnahmen - Planung, Steuerung und Begleitung von Cyber Security Assessments - Eigenständige Durchführung von Audits und Sicherheitsbewertungen im Lieferantenumfeld - Analyse und Bewertung von Cyber Security Risiken entlang der Lieferkette - Beratung interner und externer Stakeholder zu Cyber Security Fragestellungen - Unterstützung bei der Implementierung und Optimierung von Risikomanagementprozessen - Funktion als zentraler Experte im Third Party Cyber Risk Management Prozess Qualifications - Abgeschlossenes Studium der Informatik, Wirtschaftsinformatik, Medieninformatik oder eine vergleichbare Qualifikation - Mehrjährige Berufserfahrung im Cyber Security Risk Management - Erfahrung im Bereich Third Party Cyber Security Risk Management - Kenntnisse in Cyber Security Architektur, Assessments und Audits - Erfahrung in der Leitung und Durchführung von Cyber Security Projekten - Erfahrung mit Online-Assessments zur Bewertung der Cybersicherheit von Lieferanten - Analytische und strukturierte Arbeitsweise - Fähigkeit, komplexe Sachverhalte verständlich zu präsentieren und zu vermitteln - Sehr gute Deutsch- und Englischkenntnisse in Wort und Schrift Benefits - 100 % Remote-Arbeit möglich - Spannende Projekte im internationalen Cyber-Security-Umfeld - Hohe Eigenverantwortung und Gestaltungsspielraum - Mitarbeit in einem erfahrenen und interdisziplinären Expertenteam - Moderne Arbeitsweisen und innovative Sicherheitsprojekte - Flache Hierarchien und wertschätzende Unternehmenskultur - Langfristiger Projekteinsatz vom 15.07.2026 bis 14.01.2028 - Vollzeitposition mit attraktiven Entwicklungsmöglichkeiten - Möglichkeit, aktiv an der Weiterentwicklung moderner Cyber-Security-Strategien mitzuwirken
Business Information Security Officer
TELUSTELUS is an award-winning, Canadian-based company that provides superior broadband and communication systems to customers throughout the northeastern Americas. Founded in 1990, TEL
• Evaluate security risks in acquired organizations and recommend solutions • Assess the security readiness of organizations TELUS plans to acquire or has acquired • Oversee the development and maturity of the acquisition security program • Provide guidance to teams across TELUS regarding compliance and security architecture • Manage multiple concurrent projects independently, delivering actionable recommendations


